Module 3 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: what preset security policies bundle (anti-spam, anti-malware, anti-phishing, Safe Links, Safe Attachments), why presets beat hand-tuning for most SMBs, which licences include what, and how to turn them on in the Microsoft Defender portal.
Turning On Preset Security Policies
One switch, a whole stack of protection
Open the email security settings in Microsoft 365 and you will find policy pages for anti-spam, anti-malware, anti-phishing, Safe Links, and Safe Attachments, each with dozens of dials. In theory you could tune every one of them yourself. In practice, almost nobody should, because half-finished tuning is how gaps creep in.
Preset security policies are Microsoft's answer. They bundle nearly all of those protections into two ready-made profiles, Standard and Strict, with settings chosen by Microsoft based on what its filters see across billions of mailboxes. You pick who each profile applies to, and that is essentially the whole job.
The clever bit is what happens afterwards. The settings inside a preset are locked and maintained by Microsoft, so when the threat landscape shifts or a best practice changes, your protection updates automatically. A custom policy you hand-built in 2023 is still sitting exactly where you left it in 2023. For most small and medium businesses, that alone settles the argument.
Ordering the set menu at a good restaurant is not a cop-out, it is trusting a kitchen that cooks these dishes hundreds of times a night. Presets are the set menu of email security. You could order a la carte and season everything yourself, but the kitchen sees more phishing emails before breakfast than your business will in a decade.
Every Microsoft 365 plan with cloud mailboxes, from Business Basic to E5, includes a baseline set of email protections, historically known as Exchange Online Protection (EOP). They are on from day one with sensible defaults. What the Standard and Strict presets do is lift each of these layers from its default settings up to Microsoft's recommended ones.
Think of it as three layers a message has to pass through before it lands in someone's inbox.
Filters junk and bulk mail on every inbound message, and keeps an eye on outbound mail too, so a compromised mailbox cannot quietly become a spam cannon. You cannot switch spam filtering off entirely, and that is deliberate.
Multiple scanning engines check every message and attachment for known malware. Anything infected is removed before it ever reaches an inbox, and this layer cannot be disabled either.
Examines the From address on incoming mail for forgery. When Microsoft is confident the sender is not who they claim to be, the message is flagged as spoofed and handled accordingly.
These three layers are included in every plan, no extra licence needed. The next unit covers the two heavy-hitters that are not, Safe Links and Safe Attachments, which the presets also switch on if your licence includes them.
The baseline layers deal with known threats. Safe Links and Safe Attachments, part of Microsoft Defender for Office 365, are built for the ones nobody has seen yet. If your licence includes them, the Standard and Strict presets turn both on at Microsoft's recommended settings.
Safe Links
Checks every link at the moment someone clicks it, not just when the email arrived. That matters because scammers often send a clean link, wait for it to sail through the filters, then flip the destination to something nasty an hour later. Safe Links catches that trick.
- Checks URLs on click, when it counts
- Works in email, Microsoft Teams, and Office apps
- Under the presets, users cannot click through a warning
- Covers internal email too, in case an account is compromised
Safe Attachments
Opens unfamiliar attachments in a sealed virtual environment (a sandbox) and watches what they actually do before the message is delivered. If the file behaves itself, the email goes through. If it starts acting like malware, it never reaches the inbox.
- Detonates unknown files in a sandbox first
- Catches brand-new malware with no known signature
- Also protects files in SharePoint, OneDrive, and Teams
- Runs in the background, users just see delivered mail
Who gets what: the licensing bit
Every plan: anti-spam, anti-malware, and spoof protection are built in for all cloud mailboxes, from Business Basic up. The presets tune these for everyone.
Defender for Office 365 Plan 1: adds Safe Links, Safe Attachments, and impersonation protection. Included in Microsoft 365 Business Premium (and, from July 2026, in E3 as well), or available as an add-on to other plans.
Good news if you have Defender: a third preset called Built-in protection already gives everyone basic Safe Links and Safe Attachments cover by default. The Standard and Strict presets tighten it, for example by removing the option to click through a Safe Links warning and covering internal email.
Both presets block unquestionably nasty mail, like malware and high-confidence phishing, in exactly the same way. Where they differ is how suspicious they are of the grey area: bulk mail, borderline spam, and messages that only look a bit off.
The baseline profile Microsoft considers suitable for most users. Firm on real threats, forgiving in the grey area.
- Spam and bulk mail go to the Junk Email folder
- Users can rescue a wrongly flagged newsletter themselves
- Phishing threshold: more aggressive (3 of 4)
- Very little day-to-day admin involvement
A more aggressive profile for people who are actively hunted: directors, finance staff, and anyone who approves payments.
- Spam and bulk mail go straight to quarantine
- An admin reviews and releases anything blocked in error
- Phishing threshold: most aggressive (4 of 4)
- More good mail gets caught, by design
The sensible split for most SMBs: put everyone in Standard. If you have people who are obvious targets, the owner, the bookkeeper, whoever pays the invoices, consider moving just those accounts to Strict. Anyone in both lands in Strict, because it always takes precedence.
One honest caveat about Strict: it quarantines more borderline mail, which means someone has to check the quarantine and release the false alarms. If nobody in your business has time for that, Strict for everyone will generate more grumbling than security. Standard everywhere is a perfectly respectable choice.
If a person is covered by both a preset and a custom policy, the preset wins. So if someone in your business once built a custom anti-spam policy with a generous allow list, be aware the preset will quietly take over for anyone assigned to it. Usually that is exactly what you want, but it is worth knowing before the phone rings.
The whole job takes about five minutes in the Microsoft Defender portal. The Standard and Strict presets are off until you turn them on and say who they apply to, so nothing changes until you finish the wizard.
- 1Sign in to the Microsoft Defender portal at security.microsoft.com. You will need the Security Administrator role (or Global Administrator, though Microsoft recommends saving that one for emergencies).
- 2In the left menu, under Email & collaboration, select Policies & rules, then Threat policies.
- 3Under the Templated policies heading, select Preset security policies.
- 4In the Standard protection section, select Manage protection settings to start the wizard.
- 5Choose who gets the baseline protections (anti-spam, anti-malware, anti-phishing). For most businesses, pick All recipients. Select Next.
- 6If your licence includes Defender for Office 365, choose who gets Safe Links and Safe Attachments. Again, All recipients is the usual answer. Select Next.
- 7On the impersonation protection page, add the people scammers love to imitate (directors, finance) and the domains of your key suppliers, plus any trusted senders the checks should skip. Select Next.
- 8Review your choices and select Confirm. Standard protection is now on.
- 9If you decided some people belong in Strict, select Manage protection settings under Strict protection and repeat the steps for just those users.
From here, Microsoft keeps the settings current for you. Expect a few extra messages in Junk or quarantine in the first week or two while things settle. If a legitimate sender keeps getting caught, resist the urge to loosen everything; report the message as a false positive instead so the filters learn.
- Microsoft Learn: Preset security policies in cloud organizations
- Microsoft Learn: Set up steps for the Standard or Strict preset security policies
- Microsoft Learn: Recommended email and collaboration threat policy settings
- Microsoft Learn: Microsoft Defender for Office 365 overview
- Microsoft Learn: Built-in security features for all cloud mailboxes
Steps were current at the time of writing (July 2026). Microsoft occasionally moves things around the Defender portal, so screens may vary slightly.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. What are preset security policies, in a sentence?
2. Which protections come with every Microsoft 365 plan, no extra licence needed?
3. What do Safe Links and Safe Attachments require?
4. Who belongs in the Strict preset?
5. Where do you actually turn the presets on?